When to Rotate Passwords
For decades, enterprise IT policy mandated password rotation every 30 to 90 days. Modern security guidance (including NIST Special Publication 800-63B) strongly advises against arbitrary password expiration.
Why Arbitrary Rotation Fails
When forced to change passwords frequently, humans adapt poorly:
- Appending an incrementing number (Password123 -> Password124).
- Cycling through seasons (Winter2023 -> Spring2024).
- Writing passwords down on sticky notes.
Attackers know these patterns. If they crack your base password, they instantly know your future passwords.
When SHOULD You Rotate?
- Evidence of Compromise: If a service announces a breach, change that password immediately.
- Malware Infection: If you suspect your device was compromised, rotate all credentials from a clean device.
- Shared Accounts: When a member leaves a shared access group.
Common Mistakes
- Compliance Theatre: Forcing 30-day rotation because an outdated SOC2 checklist demands it, rather than updating to modern risk-based policies.